Sceawere
Vulnerability Detail
CVE-2026-105846UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Payload CMS Open Redirect Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 8h ago
- Vendor
- payloadcms
- Product
- payload
- Attack Type
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted destination after the authentication flow completes. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-10-06T17:17:19.967Z",
"pubdate": "2026-10-06T17:17:19.967Z",
"executiveSummary": "A security vulnerability categorized as an Open Redirect exists in the Payload headless content management system. This flaw allows an unauthenticated attacker to manipulate a redirect URL parameter within the authentication workflow, enabling the redirection of guest users to arbitrary, untrusted, or malicious external domains upon successful authentication.\nThe vulnerability affects Payload versions 3.40.0 through 3.87.x and canary versions prior to 4.0.0-canary.27. By exploiting this flaw, an attacker can facilitate phishing attacks, credential harvesting, or social engineering campaigns by leveraging the perceived legitimacy of the primary domain during the post-authentication redirect process.\nThe risk is categorized as moderate, primarily impacting user trust and security posture. Exploitation requires no specific privileges, as the target is an unauthenticated guest user who must interact with a crafted link. To mitigate this risk, users must update to the patched versions where input validation and domain allow-listing have been implemented for redirect parameters.",
"technicalDetails": "The vulnerability resides in the authentication flow logic of Payload CMS, specifically in the handling of the redirect parameter responsible for returning a user to a specific location after an authentication event. The application fails to perform adequate server-side validation or canonicalization on the destination URL provided via the user-supplied query string parameter.\nBecause the application does not verify if the destination URL belongs to an approved whitelist of domains or resides within the local path structure of the application, it is susceptible to Open Redirect manipulation. When a user initiates an authentication sequence, the application caches the provided redirect parameter. Upon successful credential validation, the application invokes a response object to perform an HTTP redirect to the cached URI.\nAn attacker can exploit this by crafting a malicious URL containing a parameter such as '?redirect=https://malicious-site.com'. When a victim clicks this link and completes the authentication process, the application interprets the untrusted input as a valid navigation target. The browser, trusting the initial site's response, follows the 302/303 redirect header to the attacker-controlled destination.\nThis vulnerability is present in versions 3.40.0 through 3.87.x and early canary builds. It is classified as an Open Redirect because the application logic acts as a proxy for malicious navigation without sufficient origin validation. The attack flow involves: 1) The attacker identifying the authentication endpoint that accepts a redirect URL; 2) The attacker crafting a URL with an external destination; 3) The attacker enticing a guest user to visit the crafted link; 4) The user authenticating; 5) The server redirecting the user to the attacker-supplied, external, and untrusted domain.\nThe primary impact of this flaw is the facilitation of cross-site request forgery (CSRF) context-sensitive attacks, phishing, and the bypassing of security warnings that would otherwise appear when a user navigates directly to an untrusted site from a known secure source. As the redirect occurs after the user has been authenticated, the attacker may potentially leak session tokens or perform further actions depending on the specific client-side environment."
}